The docker group grants root-level privileges to the user
But, I guess Docker doesn't really tell you not to do this... and I feel like a lot of mac users are not used to adding sudo at the front of docker commands so... idk.
Docker does by default - it only works if you use sudo. But the docs tell you to add yourself to the docker group (which requires sudo to do). Then running docker doesn’t require sudo anymore.
Yeah, that's a terrible decision in the docs. Don't ever add a path where anything on the shell can execute user-modifyable code as root.
As soon as you do that, you lose any protection that comes from separating root users and non-root users. Because now any malicious program can just use docker to elevate its code to root.
Or don't give your user docker and use sudo to use the docker CLI to get the same effect. Hell, you could even alias docker as sudo docker to get the same feel.
Most systems I use will keep a sudo authentication session open for several minutes, so you don't have to repeatedly enter your password on every single command.
Suppose we all did read the docs. How possible is it with the complexity of a modern system to really take literally everything in account, and understand the implications oof everything to keep your system safe?
It's great that it's documented, but if security isn't the default option, it will lead to issues, and everything has become so complex, that imo correctly managing everything is literally impossible...
This is a systemic issue, not a user issue.
I don't think it would've been an issue if they just put a warning in the getting started section in the docs (or if they just have secure defaults to begin with). But currently there's no mention of it. It took almost a year for me to realise that I was running "production ready code" in root
I remember when I first needed to run containers I specifically went with podman because it doesn't require root access out of some vague fear that docker can be exploited to break my stuff. I feel validated.
Podman for the rescue. Runs fully under current user pribileges, so no sudo or other root-privileges needed to run containers.
(Especially useful for devs who want containers but should not get sudo.)
keep telling yourself that. if it was 2006 I would say you're right, but 20 years of corporate neglect and abuse has caused many developers to age out and not really give a shit anymore.
young devs don't want to just "fork it", they want to make a better product. to sell it. to IBM (or entities like them).
so yeah. you keep trusting that IBM bear in the corner won't maul you when you take a nap.
I'll stick with docker, the solution that outright refused to bend a knee to the worse corporate slaver in modern history.
How do you find running it as rootless? I have enough grief with docker as is... Don't really feel the need to further complicate things by going off the status quo.. but I'm guessing it's somewhat more secure.
Here’s a whole list of misconfigurations for specific binaries and the privileges they can accidentally provide. Useful for replacing the whale in your nightmares: https://gtfobins.org/
On the docker side, yes, it runs as root by default. If you want rootless containers, try podman.
For Claude code, no, by default it asks for every command if it's allowed to run. Either this user allowed all docker commands, allowed all commands, or allowed the to ai decide if the command is safe or not by itself (yes this is a real feature). (If this is Claude code, which I can't tell if it is)
44 Comments
uuj8za@piefed.social · 113 pts · 63d
I mean, there's a big ol' warning in the docs: https://docs.docker.com/engine/install/linux-postinstall/
But, I guess Docker doesn't really tell you not to do this... and I feel like a lot of mac users are not used to adding sudo at the front of docker commands so... idk.
SpaceNoodle@lemmy.world · 64 pts · 63d
Sounds like Docker is just inherently unsecure.
hperrin@lemmy.ca · 22 pts · 63d
In the same way that sudo is.
cornshark@lemmy.world · 56 pts · 63d
Sudo makes you enter your password and docker doesn't?
locuester@lemmy.zip · 42 pts · 63d
Docker does by default - it only works if you use sudo. But the docs tell you to add yourself to the docker group (which requires sudo to do). Then running docker doesn’t require sudo anymore.
squaresinger@lemmy.world · 52 pts · 63d
Yeah, that's a terrible decision in the docs. Don't ever add a path where anything on the shell can execute user-modifyable code as root.
As soon as you do that, you lose any protection that comes from separating root users and non-root users. Because now any malicious program can just use docker to elevate its code to root.
Zikeji@programming.dev · 27 pts · 63d
Or don't give your user docker and use sudo to use the docker CLI to get the same effect. Hell, you could even alias docker as
sudo dockerto get the same feel.tabular@lemmy.world · 9 pts · 63d
Sudo can/usually does ask for password - but if you're feeling lucky you can use sudo without a password.
(Currently doing that after repeatedly failing to install an OS and have not yet felt compelled to change it back).
mkwt@lemmy.world · 1 pts · 59d
Most systems I use will keep a sudo authentication session open for several minutes, so you don't have to repeatedly enter your password on every single command.
tabular@lemmy.world · 1 pts · 59d
It's a great feature - a necessary feature even. Tired using doas Linux port and that feature isn't supported - it was depressing.
hperrin@lemmy.ca · 4 pts · 63d
Only if you tell it to.
SirHaxalot@nord.pub · 52 pts · 63d
… and the Nextcloud developers think it’s completely reasonable to build a plugin system where you give this access to a web facing PHP application.
prettybunnys@piefed.social · 10 pts · 63d
What could possibly go wrong?
ChromaticMan@lemmy.world · 23 pts · 63d
Sadly, nobody reads docs anymore. Now that I’m thinking, people never read the docs.
racemaniac@lemmy.dbzer0.com · 4 pts · 62d
Suppose we all did read the docs. How possible is it with the complexity of a modern system to really take literally everything in account, and understand the implications oof everything to keep your system safe? It's great that it's documented, but if security isn't the default option, it will lead to issues, and everything has become so complex, that imo correctly managing everything is literally impossible... This is a systemic issue, not a user issue.
Lemmert@reddthat.com · 1 pts · 62d
I don't think it would've been an issue if they just put a warning in the getting started section in the docs (or if they just have secure defaults to begin with). But currently there's no mention of it. It took almost a year for me to realise that I was running "production ready code" in root
ghodawalaaman@programming.dev · 2 pts · 63d
AdminBot@programming.dev · 1 pts · 63d
glibg10b@lemmy.zip · 3 pts · 63d
I have never even looked at the Docker docs
blarth@thelemmy.club · 84 pts · 63d
Podman will save us from the Terminators.
craftrabbit@lemmy.zip · 69 pts · 63d
I remember when I first needed to run containers I specifically went with podman because it doesn't require root access out of some vague fear that docker can be exploited to break my stuff. I feel validated.
tatterdemalion@programming.dev · 9 pts · 63d
Rootless docker exists now. Not sure why people still don't use it.
msage@programming.dev · 9 pts · 63d
LXC! LXC! LXC!
marlowe221@lemmy.world · 67 pts · 63d
Slowly reaches for shotgun…
daniskarma@lemmy.dbzer0.com · 18 pts · 63d
I'm sorry Dave, I'm afraid I can't allow you to do that.
BlueKey@fedia.io · 56 pts · 63d
Podman for the rescue. Runs fully under current user pribileges, so no sudo or other root-privileges needed to run containers.
(Especially useful for devs who want containers but should not get sudo.)
GreenKnight23@lemmy.world · 10 pts · 63d
there's just that pesky IBM thing that's constantly hanging around in the back waiting to pull the rug you're standing on.
Ghoelian@piefed.social · 7 pts · 62d
It's all open source. If they do that it will just get forked, I don't really see the issue.
GreenKnight23@lemmy.world · 4 pts · 62d
keep telling yourself that. if it was 2006 I would say you're right, but 20 years of corporate neglect and abuse has caused many developers to age out and not really give a shit anymore.
young devs don't want to just "fork it", they want to make a better product. to sell it. to IBM (or entities like them).
so yeah. you keep trusting that IBM bear in the corner won't maul you when you take a nap.
I'll stick with docker, the solution that outright refused to bend a knee to the worse corporate slaver in modern history.
Ghoelian@piefed.social · 7 pts · 62d
¯\_(ツ)_/¯ I have faith in the open-source community. So far that's turned out pretty well.
Lemmert@reddthat.com · 5 pts · 62d
You can run docker without root as well with docker rootless
ranzispa@mander.xyz · 43 pts · 63d
TIL: uninstall docker on any machine with Claude code installed.
kunaltyagi@programming.dev · 24 pts · 63d
This was known for a decade now? That's why adding a user to docker group was always an additional step with a warning
And also why podman works the way it does
Ghoelian@piefed.social · 20 pts · 62d
Or: dont let Claude code run whatever commands it wants. Read them before allowing.
yermaw@sh.itjust.works · 7 pts · 62d
I read them. I didnt understand them but I read them. It still fucked me.
Ghoelian@piefed.social · 8 pts · 62d
Well yeah additionally: don't execute commands you don't understand. Not yourself, but especially not via claude
Baizey@feddit.dk · 3 pts · 61d
That's just letting it run any command it wants with more steps
rain_worl@lemmy.world · 1 pts · 56d
Or: dont let Claude code run
JRaccoon@discuss.tchncs.de · 38 pts · 63d
Never ever add any users to the
dockergroup. Rootless mode is cool tho (albeit with some caveats)YeahToast@aussie.zone · 1 pts · 62d
How do you find running it as rootless? I have enough grief with docker as is... Don't really feel the need to further complicate things by going off the status quo.. but I'm guessing it's somewhat more secure.
savvywolf@pawb.social · 33 pts · 63d
This is your regular reminder that docker isn't a sandboxing solution and shouldn't be treated as one.
Jayjader@jlai.lu · 16 pts · 62d
A good write-up I came across 2 months ago: "Your container is not a sandbox" https://emirb.github.io/blog/microvm-2026/
guitarfosec@infosec.pub · 10 pts · 62d
Here’s a whole list of misconfigurations for specific binaries and the privileges they can accidentally provide. Useful for replacing the whale in your nightmares: https://gtfobins.org/
diabetic_porcupine@lemmy.world · 3 pts · 63d
Is that normal config?
Ghoelian@piefed.social · 1 pts · 62d
On the docker side, yes, it runs as root by default. If you want rootless containers, try podman.
For Claude code, no, by default it asks for every command if it's allowed to run. Either this user allowed all docker commands, allowed all commands, or allowed the to ai decide if the command is safe or not by itself (yes this is a real feature). (If this is Claude code, which I can't tell if it is)
yermaw@sh.itjust.works · 1 pts · 62d